PDPA and AI in Singapore: What Every Employee Needs to Know in 2026
As AI tools become part of everyday work, organisations face growing concerns about personal data protection and responsible AI use. Learn how PDPA applies when employees use AI tools and what organisations should do to reduce risk.
23 Jun 2026
TL;DR:
Employees are increasingly using AI tools such as ChatGPT, Copilot, Gemini, and Claude in their daily work.
Uploading customer information, employee records, or confidential business documents into AI tools may create PDPA and data protection risks.
A major risk comes not only from the AI technology itself, but from how employees use it.
Organisations need clear AI governance policies, workforce awareness, and practical guidance on responsible AI usage.
Employees should understand what information can and cannot be shared with AI tools.
AI governance is becoming a business-wide responsibility involving HR, operations, finance, managers, and business users—not just IT teams.
Why AI Governance and PDPA Matter More Than Ever
Artificial Intelligence (AI) tools such as ChatGPT, Microsoft Copilot, Gemini, Claude, and AI-powered workplace assistants are rapidly becoming part of everyday business operations.
Employees are increasingly using AI to:
Draft emails and reports
Summarise documents
Generate marketing content
Analyse spreadsheets
Automate workflows
Support customer communications
For many SMEs, AI adoption is happening faster than internal governance can keep up.
The challenge is no longer whether employees are using AI.
In many organisations, they already are.
The bigger question is:
Are employees using AI tools safely and responsibly?
Singapore’s Budget 2026 identified AI adoption and workforce AI literacy as national priorities through initiatives such as:
National AI Council
National AI Impact Programme
SkillsFuture AI pathways
Enterprise AI transformation support schemes
At the same time, IMDA introduced the Model AI Governance Framework for Agentic AI in 2026, highlighting the importance of accountability, oversight, and responsible AI use.
For organisations, AI governance is increasingly becoming:
A workforce issue
A data protection issue
An operational resilience issue
A business continuity issue
Not simply a technology issue.
Why PDPA Is Becoming More Important in the AI Era
Many employees may not realise that uploading information into AI tools can potentially create data protection risks.
Singapore’s Personal Data Protection Act (PDPA) requires organisations to protect personal data and remain accountable for how it is collected, used, disclosed, and safeguarded.
As AI becomes more integrated into workplace processes, organisations should pay closer attention to how employees interact with AI tools when handling:
Customer information
Employee records
Supplier information
Client reports
Financial data
Operational documents
The risk often comes not from the AI technology itself, but from the information employees provide to it.
Singapore’s enforcement landscape reflects how seriously these obligations are taken. In January 2026, the PDPC fined People Central Pte Ltd S$17,500 after a data breach resulted in the exfiltration of personal data belonging to 95,000 individuals. In the same month, Singapore Data Hub Pte Ltd was fined S$17,500 following a breach involving 689,000 individuals. Both cases involved inadequate access controls and insufficient security measures — the same risks that unmanaged employee AI usage can amplify.
Common Workplace Situations That May Create PDPA Risks
Workplace Activity | Potential Risk |
|---|---|
Uploading customer lists into public AI tools | Unauthorised disclosure of personal data |
Using employee information in AI prompts | Employee privacy concerns |
Sharing HR documents with AI systems | Exposure of confidential information |
Using personal AI accounts for work | Loss of organisational oversight |
Copying client reports into AI tools | Excessive disclosure of sensitive information |
Using NRIC numbers for customer authentication in AI-enabled systems | PDPA breach — all private organisations must cease using NRIC for authentication by 31 December 2026 (PDPC, February 2026) |
Many of these situations occur unintentionally.
The issue is often a lack of awareness rather than malicious intent.
How Employees Can Use AI Without Exposing Personal Data
Before entering information into any AI tool, employees should ask three simple questions.

1. Does This Contain Personal Data?
Examples include:
Customer names
NRIC numbers
Mobile numbers
Email addresses
Employee information
Medical information
If personal data is involved, employees should follow company policies and approved AI usage guidelines.
2. Would I Be Comfortable If This Information Was Shared Outside My Organisation?
Examples include:
Client proposals
Pricing information
Internal reports
Business strategies
Supplier agreements
If the answer is no, employees should avoid uploading the information into public AI platforms.
3. Am I Using an Approved AI Platform?
Employees should:
Use approved enterprise AI solutions
Follow organisational AI policies
Understand governance requirements
Seek clarification when unsure
Personal AI accounts should generally not be used for company work.
AI Safety Checklist for Employees
Safe Practices
✓ Use approved AI platforms
✓ Remove personal identifiers whenever possible
✓ Verify AI-generated outputs
✓ Follow company AI policies
✓ Ask for guidance when uncertain
Avoid
✗ Uploading customer databases
✗Sharing employee records
✗ Pasting confidential contracts
✗ Using personal AI accounts for work
✗ Assuming AI-generated information is always accurate
Build AI Governance and Data Protection Awareness Across Your Organisation
As employees increasingly use AI tools in their daily work, organisations need practical awareness training that combines responsible AI usage, data protection, and operational best practices.
Why Workforce Awareness Matters More Than Policies Alone
One of the most common misconceptions is:
“PDPA compliance is the responsibility of the Data Protection Officer.”
In reality:
HR handles employee information
Sales handles customer information
Finance handles sensitive records
Operations handles supplier information
Managers increasingly use AI tools
This means PDPA awareness must become an organisation-wide capability.
The strongest protection is not simply technology.
It is a workforce that understands:
Data protection responsibilities
Responsible AI usage
Organisational policies
Accountability requirements
Practical risk management
Practical First Steps Organisations Can Take
Organisations do not need highly complex AI governance frameworks to get started.
Practical first steps include:
Defining approved AI usage policies
Identifying sensitive data categories
Training employees on safe AI practices
Establishing human review processes
Clarifying accountability for AI-generated outputs
Monitoring emerging AI-related risks
Reviewing authentication methods to ensure NRIC numbers are no longer used for customer or employee authentication in any AI-enabled system — all private organisations must comply by 31 December 2026
Aligning data protection practices with SS 714:2025, the updated national standard for data protection in Singapore that superseded earlier frameworks in late 2025
SMEs may also explore SkillsFuture and workforce development initiatives that support AI literacy, responsible AI adoption, and digital capability building.
Conclusion
AI adoption across Singapore organisations is accelerating rapidly.
However, successful AI adoption depends not only on technology.
It also depends on:
Workforce awareness
Governance maturity
Operational oversight
Responsible usage practices
Employees increasingly play a direct role in protecting:
Personal data
Customer trust
Business reputation
Organisational resilience
Organisations that combine AI adoption with strong governance and workforce capability will be better positioned to improve productivity while maintaining trust and compliance.
The priority is no longer simply deploying AI tools.
It is ensuring employees know how to use them responsibly.
Frequently Asked Questions
What is AI governance?
AI governance refers to the policies, processes, and oversight mechanisms organisations use to ensure AI systems are used responsibly, safely, and ethically.
What is Shadow AI?
Shadow AI refers to employees using AI tools without formal organisational approval or governance oversight.
Why are organisations concerned about employee AI usage?
Employees may unintentionally expose personal data, confidential information, or sensitive business information when using AI tools without proper awareness.
What information should employees avoid sharing with AI tools?
Employees should avoid sharing customer information, employee records, financial information, contracts, HR data, and internal business reports.
Why is workforce AI awareness important?
Workforce awareness helps organisations reduce avoidable risks, strengthen data protection practices, and support responsible AI adoption.
References
Infocomm Media Development Authority (IMDA). (2026, January). Model AI Governance Framework for Agentic AI.
Ministry of Finance Singapore. (2026, February). Singapore Budget 2026: Harness AI as a Strategic Advantage.
Personal Data Protection Commission (PDPC). (2026). Personal Data Protection Act (PDPA) overview and guidance.
Personal Data Protection Commission (PDPC). (2026). Public consultation on advisory guidelines for the use of personal data in AI recommendation and decision systems. [Note: The finalised Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems were published on 1 March 2024, following a public consultation that closed in August 2023. Reference should read: Personal Data Protection Commission (PDPC). (2024, March 1). Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems. https://www.pdpc.gov.sg
Personal Data Protection Commission (PDPC). (2026, February 2). PDPC announces that private organisations must cease using NRIC numbers for authentication by 31 December 2026.https://www.pdpc.gov.sg
Personal Data Protection Commission (PDPC). (2026, January). Enforcement decisions: People Central Pte Ltd and Singapore Data Hub Pte Ltd. https://www.pdpc.gov.sg/enforcement-decisions
Singapore Standards Council / IMDA. (2025). SS 714:2025 — Singapore Standard for Data Protection Management System.https://www.enterprise.gov.sg/resources/standards-e-services/singapore-standards/
Personal Data Protection Commission (PDPC). (2024, March 1). Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems.https://www.pdpc.gov.sg
To learn more about the IT industry, contact us today.
Contact usGet the latest news and insights and stay up-to-date with ITEL
Recent articles


AI and Security in Retail & eCommerce: What Singapore Businesses Need to Prepare for in 2026
Retail and eCommerce businesses face increasing pressure to deliver faster, more personalised, and seamless customer experiences. Consumers today expect: Personalised recommendations, Faster customer support, Omnichannel shopping experiences, Efficient order fulfilment.
Read articleAgentic AI for Smart Manufacturing: Enabling Industry 5.0
Discover how Agentic AI is shaping the next generation of Smart Manufacturing in Singapore and why workforce readiness, governance, and operational transformation matter for Industry 5.0.
Read article